Adds CSRF protection for enabling and disabling splits.
Mark disabled tests as skipped. Fix phpcs errors. Fix email obfuscation problem.
Adds CSRF protection to client enable routes.
Fixes SA-CONTRIB-2025-008
Shubham Rathore, shelane, shubhamrathore01
Issues: 1 issues resolved.
Changes since 8.x-1.23:
This is a security release for Google Tag 2.x. No other changes have been made since 2.0.7.
Google Tag - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-011 Google Tag - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-012
NOTES - This release is compatible with Drupal 8.8, 8.9, 9.x, or 10.x. - It may be necessary to apply the core patch in #3114467: 'Negate' form value for condition plugins should be cast to boolean in validation. if the GTM snippets are no longer added to the page. This applies if other modules defining condition plugins are used on the site.